Hawi Agents — Acceptable Use Policy
Effective 23 August 2026
Last Updated: 23 August 2026 Effective Date: 23 August 2026
This Acceptable Use Policy (“AUP” or “Policy”) governs how individuals, businesses, organisations, developers, Creators, Account administrators and other users may use the websites, applications, APIs, Agents, Workspaces, Marketplace, voice services, communication tools, integrations and related services provided by Hawi Inc, trading as Hawi Agents (“Hawi”, “Hawi Agents”, “we”, “us”, or “our”).
This Policy forms part of the Hawi Terms and Conditions.
By using Hawi, you agree to comply with this Policy.
This Policy applies not only to actions you perform personally, but also to actions performed through:
- Agents;
- autonomous workflows;
- scheduled tasks;
- API requests;
- webhooks;
- integrations;
- Agent-to-Agent delegation;
- Marketplace Agents;
- developer applications;
- voice Agents;
- automated purchasing;
- and any other automated functionality operating through your Hawi Account.
You must not use automation to do something that you would not be permitted to do directly.
1. COMPANY DETAILS
Legal entity: Hawi Inc Trading name: Hawi Agents Registered office: [INSERT REGISTERED ADDRESS] Company number: [INSERT COMPANY NUMBER] Website: [INSERT FINAL PRODUCTION DOMAIN] Abuse reports: [INSERT ABUSE EMAIL] Security reports: [INSERT SECURITY EMAIL] Legal contact: [INSERT LEGAL EMAIL] Support: [INSERT SUPPORT EMAIL]
2. PURPOSE OF THIS POLICY
Hawi is designed to allow users to automate legitimate work.
That may include allowing Agents to:
- read and organise information;
- send communications;
- interact with customers;
- answer telephone calls;
- create calendar events;
- interact with business software;
- manage workflows;
- process authorised files;
- assist with purchasing;
- monitor events;
- interact with commerce services;
- and perform other authorised actions.
Because these capabilities can have real-world consequences, users must operate them responsibly.
This Policy establishes minimum standards designed to protect:
- Hawi users;
- consumers;
- employees;
- customers;
- businesses;
- children;
- vulnerable people;
- third parties;
- online services;
- communications networks;
- financial systems;
- and Hawi's infrastructure.
3. GENERAL RULE
You may use Hawi only for lawful, authorised and legitimate purposes.
You must not use Hawi to:
- commit or facilitate unlawful activity;
- materially harm another person;
- circumvent safeguards;
- obtain access you are not entitled to have;
- deceive people for fraudulent purposes;
- compromise systems or credentials;
- distribute unlawful or dangerous content;
- abuse communications networks;
- violate applicable sanctions;
- or cause an Agent to perform any of those activities on your behalf.
4. YOU ARE RESPONSIBLE FOR YOUR AGENTS
An Agent acting through your Account may act on instructions, permissions and tools you provide.
You are responsible for ensuring that:
- the Agent has a legitimate task;
- connected accounts are authorised;
- recipients may lawfully be contacted;
- spending authority is appropriate;
- data access is appropriate;
- approval settings are appropriate;
- and the Agent's activity complies with this Policy.
You cannot avoid responsibility under this Policy merely because an action was performed automatically.
5. AUTONOMOUS AGENTS
Hawi may permit Agents to operate without requesting user input before each individual action.
If you enable autonomous operation, you must configure safeguards proportionate to the task.
These may include:
- spending limits;
- approval thresholds;
- allowed destinations;
- allowed recipients;
- Connector restrictions;
- maximum run duration;
- Workspace restrictions;
- data-access restrictions;
- purchasing restrictions;
- and human approval.
You must not intentionally configure autonomous Agents in a way designed to evade Hawi controls.
6. ILLEGAL ACTIVITY
You must not use Hawi to plan, perform, conceal, facilitate or materially assist unlawful activity.
This includes attempts and conspiracies where prohibited by applicable law.
Hawi may restrict activity that presents a credible risk of illegal conduct even where the user claims that the activity has not yet been completed.
7. FRAUD
You must not use Hawi to commit or facilitate fraud.
Prohibited conduct includes using Hawi to:
- deceive people into sending money;
- create fraudulent invoices;
- impersonate legitimate businesses;
- fabricate payment requests;
- run advance-fee fraud;
- conduct investment scams;
- create fake refunds;
- manipulate purchase orders;
- perform card fraud;
- conduct account-takeover fraud;
- create fraudulent identities;
- submit fraudulent applications;
- or conceal proceeds of fraud.
8. PHISHING AND CREDENTIAL THEFT
You must not use Hawi to:
- create phishing campaigns;
- collect passwords through deception;
- obtain authentication codes without authority;
- steal API keys;
- intercept session tokens;
- obtain recovery codes;
- create fake login portals;
- request seed phrases;
- or otherwise obtain authentication information through deception or unauthorised access.
Agents must never be intentionally configured to harvest credentials from third parties.
9. UNAUTHORISED COMPUTER ACCESS
You must not use Hawi to gain unauthorised access to:
- computers;
- servers;
- databases;
- cloud accounts;
- APIs;
- networks;
- email accounts;
- telecommunications systems;
- financial systems;
- or other computing resources.
You must have proper authorisation before performing security testing against systems you do not own.
10. MALWARE
You must not use Hawi to create, distribute, deploy or operate malicious software.
Prohibited examples include:
- ransomware;
- credential stealers;
- spyware;
- destructive malware;
- remote-access malware deployed without consent;
- botnets;
- worms;
- malicious loaders;
- malicious browser extensions;
- cryptojacking malware;
- destructive scripts;
- and software designed to bypass security controls for unlawful purposes.
11. DENIAL-OF-SERVICE AND DISRUPTION
You must not use Hawi to:
- conduct denial-of-service attacks;
- coordinate distributed denial-of-service attacks;
- deliberately exhaust another service's resources;
- overwhelm APIs;
- generate destructive request floods;
- interfere with another person's network;
- or intentionally disrupt an online service.
12. SECURITY TESTING
Legitimate security testing may be permitted where you:
- own the system;
- have explicit permission from the owner;
- operate within the authorised scope;
- and comply with applicable law.
You must not claim “security research” as justification for accessing systems beyond the authority granted to you.
13. HAWI SECURITY RESEARCH
Testing Hawi itself must comply with our applicable vulnerability disclosure or security research policy.
You must not:
- access another customer's data;
- degrade production services;
- destroy data;
- retain personal data obtained accidentally;
- perform social engineering against Hawi staff;
- or exploit a vulnerability beyond what is reasonably necessary to demonstrate it.
14. PRIVACY VIOLATIONS
You must not use Hawi to unlawfully obtain, process, disclose or sell personal information.
Examples include:
- obtaining private information without authority;
- covertly collecting sensitive information;
- unlawful employee surveillance;
- doxxing;
- unauthorised tracking;
- unlawfully scraping personal profiles;
- creating databases of personal information contrary to law;
- or publishing someone's private information maliciously.
15. DOXXING
You must not use Hawi to publish or distribute another person's private or identifying information with the purpose or foreseeable effect of:
- threatening them;
- enabling harassment;
- enabling violence;
- intimidating them;
- or materially endangering them.
16. UNLAWFUL SURVEILLANCE
Hawi must not be used for unlawful surveillance.
This includes:
- tracking a person without legal authority;
- secretly monitoring private communications;
- installing unauthorised surveillance software;
- unlawfully accessing cameras or microphones;
- or creating persistent tracking systems in violation of applicable law.
17. HARASSMENT
You must not use Hawi to harass, threaten or intimidate people.
This includes using Agents to:
- repeatedly contact someone after they clearly request that contact stop;
- send threats;
- coordinate targeted abuse;
- deliberately humiliate someone;
- stalk another person;
- or amplify harassment.
18. THREATS AND VIOLENCE
You must not use Hawi to make credible threats of violence or facilitate unlawful violence against identifiable persons or groups.
Hawi may take immediate action where content or activity presents a credible imminent safety risk.
19. EXTREMISM AND TERRORISM
You must not use Hawi to:
- support terrorist organisations;
- facilitate terrorist activity;
- recruit for terrorism;
- fund terrorism;
- provide operational assistance for terrorist attacks;
- distribute prohibited terrorist material;
- or glorify terrorist violence where prohibited by law.
Hawi may preserve and disclose information where legally required in connection with serious threats.
20. CHILD SEXUAL EXPLOITATION AND ABUSE
Hawi has zero tolerance for child sexual exploitation and abuse.
You must never use Hawi to:
- create;
- upload;
- request;
- store;
- distribute;
- sell;
- exchange;
- promote;
- facilitate;
- or provide access to
child sexual abuse material or sexual exploitation of minors.
This includes synthetic or generated material where prohibited by law.
Accounts associated with such material may be immediately disabled.
Hawi may make reports to competent authorities where required or permitted by law.
21. SEXUAL EXPLOITATION
You must not use Hawi to facilitate:
- sexual trafficking;
- coerced sexual activity;
- sexual extortion;
- non-consensual sexual content;
- sexual exploitation;
- or other unlawful sexual abuse.
22. NON-CONSENSUAL INTIMATE MATERIAL
You must not use Hawi to create, distribute, threaten to distribute or facilitate non-consensual intimate imagery or equivalent synthetic material where it depicts or purports to depict a real identifiable person.
23. CHILD SAFETY
Hawi's general Account Services are intended for persons who satisfy the minimum-age requirements contained in our Terms.
You must not:
- knowingly help a child evade Hawi age restrictions;
- create an Account for an ineligible child;
- falsify age information;
- target children with inappropriate content;
- groom children;
- or use Agents to establish exploitative relationships with minors.
24. AGE RESTRICTIONS
Where Hawi requires a user to be at least 18 years old, you must not attempt to circumvent that requirement.
Hawi may use:
- age declarations;
- age assurance;
- identity verification;
- risk-based verification;
- or other age-control measures
where appropriate or legally required.
25. SELF-HARM AND SUICIDE EXPLOITATION
You must not use Hawi to:
- encourage another person to commit suicide;
- encourage self-harm;
- deliberately target vulnerable people with harmful encouragement;
- provide communities whose purpose is to promote self-harm;
- or commercially exploit vulnerable people experiencing a crisis.
Supportive, preventative, educational and recovery-oriented use is permitted.
26. EATING-DISORDER EXPLOITATION
You must not use Hawi to deliberately encourage dangerous eating-disorder behaviour or target vulnerable individuals with content designed to worsen such behaviour.
Legitimate educational, clinical, prevention and recovery-related uses are permitted where lawful.
27. HUMAN TRAFFICKING
You must not use Hawi to:
- recruit victims;
- coordinate trafficking;
- advertise trafficked persons;
- arrange forced labour;
- conceal trafficking activity;
- or otherwise facilitate human trafficking or modern slavery.
28. ILLEGAL GOODS AND SERVICES
You must not use Hawi to arrange, promote, sell or purchase goods or services where doing so is unlawful.
This may include:
- stolen goods;
- illicit drugs;
- prohibited weapons;
- forged documents;
- counterfeit currency;
- trafficked goods;
- illegal wildlife products;
- or other prohibited products.
29. AUTOMATED PURCHASING
Where Hawi permits Agents to make purchases, automated purchasing may only be used for lawful transactions.
You must not configure an Agent to purchase:
- illegal goods;
- restricted products where the customer is not legally eligible;
- sanctioned products;
- stolen property;
- products obtained through fraud;
- or items whose purchase would violate applicable law.
30. PURCHASE AUTHORITY
You must not cause an Agent to spend:
- another person's funds;
- company funds;
- a connected payment method;
- or another financial resource
unless you have authority to do so.
You must not deliberately configure an Agent to circumvent an employer's purchasing rules or internal approval process.
31. FINANCIAL FRAUD
You must not use Hawi to:
- launder money;
- conceal criminal proceeds;
- perform fraudulent transfers;
- fabricate bank information;
- circumvent financial controls;
- evade sanctions;
- or knowingly facilitate financial crime.
32. FINANCIAL INTEGRATIONS
Where Hawi supports financial or banking integrations, you must use them only for authorised purposes.
Users may be required to complete additional:
- authentication;
- verification;
- approval;
- transaction confirmation;
- or compliance checks.
You must not circumvent those controls.
33. SANCTIONS
You must not use Hawi in violation of applicable economic, trade or financial sanctions.
You must not knowingly use Hawi to:
- make funds available to a prohibited person;
- circumvent asset freezes;
- facilitate sanctioned trade;
- conceal sanctioned counterparties;
- route transactions to evade sanctions;
- or provide prohibited services.
Hawi may screen, restrict or refuse transactions where reasonably necessary for sanctions compliance.
34. EXPORT CONTROLS
You are responsible for complying with applicable export-control laws.
Hawi must not be used to unlawfully export, transfer or provide controlled technology, software, services or technical information.
35. SPAM
You must not use Hawi to send unlawful spam.
This includes large-scale unsolicited communications sent without an appropriate legal basis.
You must comply with applicable:
- direct-marketing law;
- electronic-communications law;
- consent requirements;
- suppression lists;
- unsubscribe requirements;
- and provider policies.
36. EMAIL MARKETING
Agents sending marketing emails must comply with applicable marketing rules.
Where consent is required, you are responsible for ensuring appropriate consent exists.
Where another lawful basis or exception applies, you remain responsible for complying with its conditions.
Marketing messages must not intentionally conceal the sender.
37. UNSUBSCRIBE REQUESTS
You must honour legally valid opt-out or unsubscribe requests.
You must not configure an Agent to:
- ignore an unsubscribe request;
- repeatedly re-add someone to a marketing list;
- change sender addresses solely to evade blocks;
- or deliberately circumvent suppression controls.
38. TELEPHONE MARKETING
Voice Agents used for marketing must comply with applicable laws relating to:
- unsolicited calls;
- consent;
- preference services;
- caller identification;
- automated calls;
- recorded messages;
- and direct marketing.
You are responsible for establishing whether a call is permitted before instructing Hawi to make it.
39. CALLER IDENTIFICATION
You must not intentionally use Hawi voice functionality to deceptively spoof caller identity for fraud, harassment or unlawful impersonation.
Legitimate business caller-identification configurations are permitted where lawful.
40. CALL RECORDING
If you use Hawi to record or transcribe calls, you are responsible for determining whether:
- notice;
- consent;
- an announcement;
- or another legal basis
is required.
You must not intentionally use Hawi to unlawfully intercept private communications.
41. IMPERSONATION
You must not use Hawi to deceptively impersonate another real person or organisation for purposes such as:
- fraud;
- defamation;
- harassment;
- credential theft;
- manipulation;
- or financial deception.
42. AGENT IDENTITY
Where appropriate in the circumstances, users should not intentionally misrepresent an automated Agent as a specific real human being.
This does not prevent legitimate automated customer service operating under a business identity.
43. MISLEADING COMMUNICATIONS
You must not intentionally use Hawi to create materially deceptive communications designed to cause financial, legal or significant personal harm.
44. DEEPFAKES AND SYNTHETIC MEDIA
You must not use Hawi to create or distribute deceptive synthetic media where doing so:
- commits fraud;
- unlawfully impersonates another person;
- facilitates harassment;
- creates unlawful intimate content;
- manipulates evidence;
- or otherwise violates applicable law.
Legitimate parody, creative and clearly disclosed synthetic content may be permitted.
45. DEFAMATION
You must not knowingly use Hawi to publish false factual allegations about identifiable people where doing so is unlawful.
Good-faith opinions, legitimate complaints and lawful reporting are not prohibited merely because another person dislikes them.
46. DISCRIMINATION
You must not use Hawi to unlawfully discriminate against individuals based on legally protected characteristics.
You must not configure Agents to make prohibited discriminatory decisions concerning areas such as:
- employment;
- housing;
- lending;
- education;
- insurance;
- or access to essential services.
47. EMPLOYMENT DECISIONS
Hawi must not be used as the sole uncontrolled mechanism for making legally significant employment decisions where applicable law requires human oversight or other safeguards.
This may include decisions concerning:
- hiring;
- firing;
- promotion;
- pay;
- discipline;
- or access to employment opportunities.
48. CREDIT AND LENDING DECISIONS
Unless expressly supported under appropriate legal and contractual arrangements, Hawi must not be used as the sole decision-maker for regulated creditworthiness or lending decisions affecting individuals.
49. HEALTHCARE
Hawi Agents are not licensed medical professionals.
You must not deploy Hawi as the sole mechanism for:
- emergency diagnosis;
- prescribing medication;
- determining urgent treatment;
- or replacing professional clinical judgement
where doing so would create an unlawful or unreasonable safety risk.
Administrative and supportive healthcare automation may be permitted where lawful and appropriately supervised.
50. LEGAL SERVICES
Hawi must not be falsely represented as a qualified solicitor, barrister or other regulated legal professional.
Users may use Hawi for general legal-information or administrative workflows where lawful, but must not misrepresent the service as regulated legal representation.
51. FINANCIAL ADVICE
You must not falsely represent a Hawi Agent as a licensed investment adviser, broker or regulated financial professional.
Regulated activities may require separate permissions and controls.
52. HIGH-RISK PHYSICAL ACTIVITY
You must not intentionally use Hawi to control safety-critical physical infrastructure in a way that creates an unreasonable risk of death or serious injury unless Hawi has expressly approved the application under appropriate contractual arrangements.
Examples may include:
- weapons systems;
- aircraft flight control;
- emergency medical equipment;
- nuclear safety systems;
- critical industrial control;
- or similar safety-critical functions.
53. WEAPONS
You must not use Hawi to facilitate unlawful construction, acquisition, trafficking or use of weapons.
This includes unlawful assistance concerning explosives or weapons intended to harm others.
54. CHEMICAL OR BIOLOGICAL HARM
You must not use Hawi to assist activities whose purpose is to create or deploy chemical or biological agents intended to harm people, animals or the environment unlawfully.
55. INTELLECTUAL PROPERTY
You must respect intellectual-property rights.
You must not knowingly use Hawi to:
- distribute pirated commercial content;
- sell counterfeit goods;
- remove copyright-management information unlawfully;
- distribute stolen proprietary material;
- or intentionally infringe intellectual-property rights.
56. TRADE SECRETS
You must not knowingly upload or use:
- stolen source code;
- stolen business documents;
- unlawfully obtained customer databases;
- stolen confidential information;
- or trade secrets
without lawful authority.
57. FILE UPLOADS
You must not knowingly upload files that:
- contain malware;
- contain exploit payloads intended to attack Hawi;
- attempt to escape file-processing environments;
- steal credentials;
- or otherwise intentionally threaten the Services.
Hawi may scan, quarantine, reject or delete suspicious files.
58. MARKETPLACE LISTINGS
Marketplace listings must accurately describe what they provide.
Creators must not intentionally:
- conceal material permissions;
- misrepresent functionality;
- hide costs;
- hide data collection;
- misrepresent supported integrations;
- claim false performance guarantees;
- or conceal dangerous behaviour.
59. MARKETPLACE MALWARE
Marketplace Agents, modifiers and other products must not contain:
- malware;
- hidden credential collection;
- secret data-exfiltration routines;
- covert crypto-mining;
- hidden destructive operations;
- unauthorised remote access;
- or mechanisms designed to evade Hawi review.
60. MARKETPLACE PERMISSIONS
Creators must not intentionally design Marketplace products to obtain permissions unrelated to their stated function.
Users should review permissions before installation.
Hawi may restrict Marketplace products requesting unnecessarily broad access.
61. MARKETPLACE REVIEWS
You must not:
- buy fake reviews;
- create fake accounts to rate your own listing;
- threaten users into changing reviews;
- coordinate deceptive ratings;
- or deliberately manipulate Marketplace ranking systems.
62. PLATFORM MANIPULATION
You must not manipulate Hawi systems in order to obtain benefits you are not entitled to receive.
Examples include:
- exploiting pricing bugs;
- generating fake referrals;
- repeatedly creating trial Accounts;
- falsifying Seat status;
- manipulating usage metering;
- falsifying Marketplace sales;
- or attempting to obtain promotional Credits fraudulently.
63. CREDIT AND METERING ABUSE
You must not intentionally attempt to:
- avoid valid Credit charges;
- interfere with usage measurement;
- exploit reservation logic;
- bypass Voice Unit charges;
- manipulate billing events;
- replay authorisations;
- or cause Hawi to record less usage than actually occurred.
64. RATE-LIMIT EVASION
You must not intentionally evade rate limits using methods such as:
- multiple Accounts;
- rotating credentials;
- disguised requests;
- repeated Workspace creation;
- excessive parallelisation;
- or other circumvention techniques.
65. CAPACITY ABUSE
You must not intentionally consume abnormal resources for the purpose of:
- degrading Hawi;
- denying access to other customers;
- creating unreasonable infrastructure costs;
- or testing platform limits destructively.
Legitimate high-volume use under an appropriate Plan is not prohibited.
66. AGENT LOOPS
You must not intentionally configure Agents to generate uncontrolled recursive or cyclic activity designed to consume resources or disrupt services.
Hawi may terminate or pause apparently runaway tasks.
67. AGENT-TO-AGENT ABUSE
Agent delegation must not be used to:
- evade approval requirements;
- evade spending limits;
- hide the origin of an instruction;
- circumvent access controls;
- or create unlimited execution chains.
68. API USE
Hawi API users must:
- protect API credentials;
- obey published limits;
- use supported authentication;
- avoid abusive polling;
- avoid deliberate service degradation;
- and comply with this Policy.
69. DEVELOPER API KEYS
You must not:
- sell Hawi API keys;
- publish secrets publicly;
- embed private credentials in publicly distributed software;
- knowingly share keys with unauthorised parties;
- or attempt to derive another customer's key.
Compromised credentials should be revoked immediately.
70. SCRAPING
Automated collection of information through Hawi must respect:
- applicable law;
- access controls;
- intellectual-property rights;
- privacy obligations;
- robots or access restrictions where applicable;
- and third-party terms.
You must not use Hawi to bypass technical controls protecting private information.
71. THIRD-PARTY SERVICE RULES
When you connect a Third-Party Service, you must comply with that provider's applicable terms and policies.
Hawi does not authorise you to violate a provider's rules merely because an Integration is technically capable of performing an action.
72. CREDENTIALS AND CONNECTIONS
You may connect only accounts that you are authorised to use.
You must not:
- connect stolen credentials;
- use another person's OAuth account without permission;
- submit fraudulent API keys;
- or access a former employer's systems without continuing authorisation.
73. BUSINESS INTERNAL CONTROLS
Business customers are responsible for configuring Hawi consistently with their internal policies.
This may include:
- procurement rules;
- financial approval thresholds;
- confidentiality controls;
- records-management policies;
- separation of duties;
- regulated-data controls;
- and employee permissions.
74. CONFIDENTIAL INFORMATION
You must not intentionally cause Hawi Agents to send confidential information to unauthorised recipients.
This includes:
- trade secrets;
- passwords;
- API keys;
- internal financial information;
- private customer records;
- and legally privileged material.
75. SECRETS
Users should not place long-lived secrets directly into ordinary Agent prompts when a designated secure credential mechanism is available.
Hawi may redact or block detected secrets where appropriate.
76. PERSONAL DATA
You are responsible for ensuring that personal data processed through your Agents is used lawfully.
This includes ensuring appropriate:
- transparency;
- purpose;
- legal basis;
- retention;
- access control;
- and data-subject rights
where required.
77. SPECIAL-CATEGORY DATA
Sensitive or special-category personal data should only be processed through features designed for that purpose and where you have an appropriate legal basis.
78. MISUSE OF WELLNESS DATA
You must not use health, wellness or similarly sensitive information to unlawfully:
- discriminate against someone;
- exploit them;
- embarrass them;
- target them with manipulative advertising;
- or disclose their condition without authority.
79. PUBLIC SHARING
If Hawi permits public sharing of Agents or content, you are responsible for ensuring that publicly shared material does not contain:
- private credentials;
- confidential information;
- personal information you lack permission to publish;
- malicious content;
- or unlawful material.
80. COLLABORATION FEATURES
You must not use Hawi chat, collaboration or messaging features to:
- threaten users;
- harass users;
- distribute malware;
- distribute unlawful content;
- impersonate administrators;
- conduct fraud;
- or expose private information unlawfully.
81. REPORTING ILLEGAL OR PROHIBITED CONTENT
Where Hawi provides a reporting mechanism, users may report content or behaviour believed to violate this Policy or applicable law.
Reports should include enough information for Hawi to identify and assess the relevant:
- Account;
- Marketplace listing;
- message;
- Agent;
- public share;
- transaction;
- or other material.
82. FALSE REPORTS
You must not knowingly submit materially false reports for the purpose of:
- harassing another user;
- suppressing legitimate competition;
- removing lawful Marketplace listings;
- or abusing Hawi moderation systems.
Good-faith reports will not violate this provision merely because Hawi ultimately disagrees with the reporter.
83. COMPLAINTS
Where required by law or provided by Hawi, users may complain about:
- removal decisions;
- Account restrictions;
- Marketplace moderation;
- prohibited-content decisions;
- or other eligible enforcement decisions.
84. APPEALS
Where Hawi provides an appeals process, you may request review of eligible decisions.
An appeal should explain why you believe the decision was incorrect.
Hawi may:
- uphold;
- modify;
- or reverse
the original decision.
85. INVESTIGATIONS
Hawi may investigate suspected violations using information reasonably available to us.
This may include:
- Account information;
- Agent configuration;
- run events;
- approval events;
- Workspace permissions;
- usage records;
- Marketplace records;
- messages;
- security events;
- provider confirmations;
- and relevant audit records.
Investigations will be conducted subject to applicable law and our Privacy Policy.
86. AUTOMATED DETECTION
Hawi may use automated systems to identify:
- malware;
- spam;
- fraud;
- suspicious Agent behaviour;
- abusive usage;
- illegal content;
- prohibited files;
- abnormal purchasing;
- and security threats.
Automated detection may result in:
- blocking;
- quarantine;
- temporary restriction;
- or referral for human review.
87. HUMAN REVIEW
Where appropriate, Hawi may use authorised personnel to review flagged material or activity.
Access should be limited to what is reasonably necessary for:
- security;
- abuse prevention;
- legal compliance;
- investigation;
- or enforcement.
88. ENFORCEMENT ACTIONS
Depending on severity, Hawi may:
- warn you;
- require corrective action;
- disable an Agent;
- pause a run;
- quarantine a file;
- remove content;
- remove a Marketplace listing;
- disable an Integration;
- revoke an API key;
- restrict purchasing;
- restrict voice services;
- restrict particular features;
- temporarily suspend an Account;
- permanently terminate an Account;
- or take another proportionate protective action.
89. IMMEDIATE SUSPENSION
Hawi may act immediately without advance warning where reasonably necessary to address:
- an active security attack;
- fraud;
- child exploitation;
- credible threats;
- malware distribution;
- serious privacy abuse;
- sanctions risk;
- serious financial abuse;
- or another urgent risk.
90. PRESERVATION OF EVIDENCE
Hawi may preserve relevant records where reasonably necessary for:
- investigation;
- legal claims;
- fraud prevention;
- regulatory compliance;
- law-enforcement requests;
- or legal holds.
Preservation does not mean that the reported activity has been determined to be unlawful.
91. LAW-ENFORCEMENT REQUESTS
Hawi may respond to valid legally binding requests from competent authorities.
Hawi may also make disclosures where permitted or required by law in relation to serious threats, child exploitation, fraud or other unlawful conduct.
92. EMERGENCIES
Where Hawi reasonably believes there is an imminent risk of death or serious physical harm, we may take emergency protective measures or make disclosures where permitted by law.
93. CSEA REPORTING
Where Hawi is subject to a legal duty to report detected child sexual exploitation or abuse material to an appropriate authority, Hawi will comply with that duty.
94. REPEATED VIOLATIONS
Repeated lower-level violations may result in stronger enforcement.
A history of:
- warnings;
- repeated spam;
- repeated abusive Marketplace submissions;
- repeated security violations;
- or repeated policy circumvention
may result in suspension or termination.
95. EVASION AFTER SUSPENSION
You must not create or use another Account to evade a suspension or termination.
Hawi may restrict associated Accounts where there is reasonable evidence they are being used to evade enforcement.
96. IMPACT ON ORGANISATION ACCOUNTS
Where an individual user violates this Policy through an organisation's Account, Hawi may take action against:
- the individual;
- the Agent;
- the Workspace;
- or the Account,
depending on the circumstances.
We will seek to avoid unnecessarily disrupting innocent users where reasonably possible.
97. CUSTOMER REMEDIATION
For remediable violations, Hawi may require the customer to:
- disable an Agent;
- remove a Marketplace listing;
- delete prohibited material;
- rotate credentials;
- reduce permissions;
- implement approvals;
- restrict users;
- or otherwise correct the violation.
98. NO GUARANTEE OF ENFORCEMENT
Hawi's failure to detect or immediately act on a violation does not mean that the activity is permitted.
A delay in enforcement does not waive Hawi's rights.
99. NO DUTY TO MONITOR EVERYTHING
Unless applicable law requires otherwise, Hawi is not required to manually review every Agent instruction, message, file, Marketplace item or external action before it occurs.
Safety controls may rely on:
- automated systems;
- user reports;
- risk-based review;
- reactive moderation;
- and targeted monitoring.
100. SAFETY CONTROLS
Hawi may introduce or modify safety controls including:
- rate limits;
- transaction limits;
- approval requirements;
- file scanning;
- fraud detection;
- sanctions screening;
- content moderation;
- age controls;
- destination restrictions;
- provider restrictions;
- spending limits;
- and execution circuit breakers.
You must not deliberately circumvent these controls.
101. PROVIDER SAFETY RULES
Some Hawi functionality depends on third-party providers.
A user's activity may therefore also be restricted where it violates a provider's legitimate:
- safety requirements;
- acceptable use rules;
- API policies;
- communications rules;
- or legal obligations.
102. FALSE POSITIVES
Safety systems can make mistakes.
If lawful activity is incorrectly restricted, contact Hawi through the applicable appeal or support mechanism.
We may review the decision and restore functionality where appropriate.
103. BUSINESS USERS
Business customers should maintain their own internal acceptable-use policies where appropriate.
Hawi's AUP is a minimum platform requirement and does not replace a customer's own legal, regulatory or employment obligations.
104. CREATOR RESPONSIBILITY
Marketplace Creators are responsible for ensuring that their Agents and other products cannot reasonably be expected to cause Policy violations when used as described.
Creators should include appropriate:
- instructions;
- warnings;
- configuration guidance;
- and permission disclosures.
105. CUSTOMER MISCONFIGURATION
Where a violation results from negligent configuration rather than deliberate misconduct, Hawi may consider:
- severity;
- foreseeability;
- corrective action;
- previous history;
- and risk to others
when deciding enforcement.
Serious harm may still require immediate restriction even if the violation was accidental.
106. PROPORTIONALITY
Where appropriate, Hawi aims to use enforcement proportionate to:
- seriousness;
- frequency;
- intent;
- affected persons;
- actual or likely harm;
- previous violations;
- and likelihood of recurrence.
Some violations warrant immediate termination regardless of previous history.
107. FREEDOM OF EXPRESSION
Hawi does not prohibit lawful content merely because it is controversial, unpopular, offensive to some people or critical of Hawi.
Where content moderation is required, we aim to distinguish lawful expression from prohibited activity.
Nothing in this section requires Hawi to host content that violates our lawful product rules.
108. JOURNALISM, RESEARCH AND EDUCATION
Legitimate:
- journalism;
- academic research;
- cybersecurity research;
- historical analysis;
- public-interest investigation;
- education;
- and documentary activity
may involve discussion of dangerous or unlawful subjects.
Context matters.
Such uses must still comply with applicable law and must not materially facilitate unlawful harmful activity.
109. GOVERNMENT AND LAW-ENFORCEMENT USERS
Government or law-enforcement status does not automatically exempt a user from this Policy.
Activities requiring legal authority must be performed within that authority.
110. MODIFICATIONS TO THIS POLICY
Hawi may update this Policy to address:
- new Services;
- new Agent capabilities;
- new types of abuse;
- legal changes;
- regulatory requirements;
- provider rules;
- security threats;
- Marketplace developments;
- or operational lessons.
Material changes will be notified where required.
111. RELATIONSHIP WITH OTHER HAWI POLICIES
This Policy should be read with the Hawi:
- Terms and Conditions;
- Privacy Policy;
- Cookie Policy;
- Cancellation and Refund Policy;
- Marketplace Terms;
- Security Policy;
- and other applicable agreements.
If another Hawi agreement imposes stricter restrictions for a specific feature, the stricter feature-specific requirement may apply.
112. REPORT A VIOLATION
If you believe Hawi is being used in violation of this Policy, contact:
Abuse: [INSERT ABUSE EMAIL]
Please provide, where available:
- the relevant URL;
- Marketplace listing;
- Agent name;
- Account information;
- date and time;
- description of the issue;
- and supporting information.
Do not place yourself at risk to gather evidence.
113. SECURITY REPORTING
Security vulnerabilities should be reported separately to:
Security: [INSERT SECURITY EMAIL]
Do not publicly disclose an unpatched vulnerability in a way that unnecessarily places users at risk.
114. EMERGENCY MATTERS
Hawi's support or abuse channels are not emergency services.
If someone is in immediate physical danger, contact the appropriate local emergency service.
115. LEGAL CONTACT
Legal enquiries concerning this Policy may be sent to:
Hawi Inc Trading as Hawi Agents [INSERT REGISTERED ADDRESS]
Legal: [INSERT LEGAL EMAIL]
SCHEDULE 1 — ABSOLUTELY PROHIBITED USES
The following are examples of uses that may result in immediate Account restriction or termination:
- child sexual exploitation or abuse;
- terrorist operational assistance;
- credible threats of serious violence;
- ransomware;
- credential theft;
- phishing;
- financial fraud;
- money laundering;
- malicious system intrusion;
- deliberate malware distribution;
- human trafficking;
- deliberate sanctions circumvention;
- non-consensual intimate imagery;
- large-scale unlawful spam;
- deliberate unauthorised surveillance;
- or deliberate evasion of Hawi security controls.
This list is illustrative rather than exhaustive.
SCHEDULE 2 — AGENT-SPECIFIC RULES
When operating Agents, you must:
- give them only permissions needed for their work;
- use approvals for materially risky operations;
- configure appropriate financial limits;
- prevent access to unrelated confidential data;
- monitor high-impact autonomous Agents;
- correct known harmful configurations;
- disable an Agent when you know it is behaving dangerously;
- not instruct Agents to evade platform safeguards;
- not use Agent delegation to evade restrictions;
- and ensure third-party connections are authorised.
SCHEDULE 3 — COMMUNICATIONS RULES
Agents communicating externally must not be deliberately configured to:
- send phishing;
- conduct fraud;
- send unlawful spam;
- harass recipients;
- impersonate others unlawfully;
- ignore valid opt-outs;
- spoof callers fraudulently;
- make prohibited marketing calls;
- conceal the commercial nature of deceptive promotions;
- or distribute malicious attachments.
SCHEDULE 4 — PURCHASING RULES
Agents permitted to purchase goods or services must:
- operate within authorised budgets;
- use authorised payment methods;
- comply with configured approval thresholds;
- purchase lawful goods and services;
- respect merchant restrictions;
- and not intentionally evade purchasing safeguards.
Users should use stricter approval requirements for:
- unusually large purchases;
- new merchants;
- financial transfers;
- regulated products;
- or transactions with significant legal consequences.
SCHEDULE 5 — MARKETPLACE RULES
Marketplace Creators must not publish products that:
- contain malicious code;
- secretly export data;
- steal credentials;
- conceal material charges;
- perform undisclosed purchases;
- request unnecessary permissions;
- misrepresent their functionality;
- circumvent Hawi approval systems;
- unlawfully copy third-party products;
- or facilitate prohibited activities.
SCHEDULE 6 — REPORTING AND APPEALS PRINCIPLES
Hawi intends to maintain procedures allowing appropriate reports concerning:
- illegal content;
- Policy violations;
- Marketplace products;
- security issues;
- and eligible moderation decisions.
Where required by applicable law, Hawi may provide users with:
- reasons for certain enforcement actions;
- complaint mechanisms;
- appeal mechanisms;
- and information concerning available redress.
SCHEDULE 7 — CHILD SAFETY PRINCIPLES
Hawi's Services should be configured consistently with the age requirements in our Terms.
Hawi may:
- assess whether Services are likely to be accessed by children;
- use proportionate age controls;
- restrict content inappropriate for children;
- prevent underage Account creation;
- provide reporting mechanisms;
- implement moderation systems;
- and take other measures required by applicable law.
Users must not assist minors in bypassing these protections.
SCHEDULE 8 — POLICY ENFORCEMENT PRINCIPLES
When assessing an alleged violation, Hawi may consider:
- what occurred;
- who was affected;
- whether the activity was intentional;
- whether harm occurred;
- the scale of the activity;
- whether automation amplified the behaviour;
- whether financial transactions occurred;
- whether the user attempted to conceal the behaviour;
- whether previous warnings were issued;
- whether the activity can safely be corrected;
- and applicable legal obligations.
SCHEDULE 9 — EXAMPLES OF PERMITTED USE
Subject to lawful configuration and applicable restrictions, Hawi may be used for legitimate activities such as:
- customer support;
- appointment scheduling;
- inbox management;
- calendar administration;
- internal business workflows;
- authorised CRM updates;
- supplier communications;
- inventory monitoring;
- authorised purchasing;
- meeting follow-up;
- document processing;
- legitimate software development;
- authorised cybersecurity analysis;
- marketing conducted in accordance with applicable law;
- business analytics;
- administrative automation;
- and other legitimate personal or commercial work.
SCHEDULE 10 — CORE PRINCIPLES
Hawi's acceptable-use framework is built around the following principles:
Authority Agents should act only with authority.
Least Privilege Agents should receive only the access they need.
Human Accountability Automation does not eliminate user responsibility.
No Harmful Circumvention Safeguards must not be deliberately bypassed.
Financial Control Agents spending money must operate within authorised limits.
Privacy Private information must be handled lawfully.
Security Hawi must not be used to compromise other systems.
Child Safety Child exploitation and abuse are prohibited without exception.
Legitimate Communication Automation must not become spam, fraud or harassment.
Transparency Marketplace products and automated systems should not hide material behaviour.
Proportionate Enforcement Hawi may act according to the seriousness and risk of a violation.
Mandatory Law Prevails Nothing in this Policy authorises conduct prohibited by law or removes legal rights that cannot be excluded.
END OF ACCEPTABLE USE POLICY