Effective 21-07-2026 · Version 1.0

Acceptable Use Policy

Provider: ERPflow OÜ, a private limited company incorporated under the laws of the Republic of Estonia (registry code: 17201984) (the "Provider", "we", "us", or "our").

Service: the ERPflow.ai software-as-a-service platform available at https://erpflow.ai and any related applications, APIs, integrations, documentation, and features (the "Service").

Supplements: General Terms and Conditions of Service v1.0

1. Purpose and status

1.1. This Acceptable Use Policy (the "AUP") sets out the rules that govern how the Customer, its users, and any third party acting on the Customer's behalf may use the Service. It supplements Section 5 of the General Terms and Conditions of Service, version 1.0 (the "GTC"), and forms part of the Agreement between the Customer and the Provider.

1.2. Terms capitalised but not defined in this AUP have the meaning given to them in the GTC. In case of conflict between this AUP and Section 5 of the GTC, the more restrictive provision prevails (GTC clause 5.3).

1.3. This AUP is addressed to B2B customers (GTC clause 1.2).

1.4. The Customer is responsible for ensuring that every person who accesses the Service through the Customer's account — including employees, contractors, agents, integrators, and any user provisioned by the Customer ("Authorised Users") — complies with this AUP. Breach by an Authorised User is treated as breach by the Customer (GTC clause 5.1(d)).

2. Lawful use

2.1. The Customer must use the Service only for lawful business purposes and in compliance with all laws, regulations, and third-party rights applicable to the Customer, its Authorised Users, and its Customer Data, including:

  • (a) Regulation (EU) 2016/679 (GDPR) and the Estonian Personal Data Protection Act;
  • (b) Regulation (EU) 2022/2065 (Digital Services Act) to the extent the Customer's own use of the Service brings it within that regulation's scope;
  • (c) Directive 2005/29/EC (Unfair Commercial Practices), Directive 2006/114/EC (Misleading and Comparative Advertising), and the applicable Consumer Protection Act;
  • (d) applicable anti–money-laundering, counter-terrorism-financing, sanctions, and export-control laws, including Council Regulation (EU) No 833/2014 (as amended), Council Regulation (EC) No 2580/2001, and equivalent US OFAC and UN sanctions regimes;
  • (e) the Estonian Copyright Act, Directive (EU) 2019/790 (DSM), and any other intellectual-property rules protecting third-party works, databases, trademarks, or trade secrets; and
  • (f) applicable tax and accounting laws (the Service is a tool, not a substitute for the Customer's professional advisers — see GTC clauses 7.2(d) and 7.3).

3. Prohibited content

3.1. The Customer must not upload, store, transmit, generate, or make available through the Service any content that:

  • (a) is unlawful, defamatory, harassing, threatening, abusive, hateful (including on grounds of race, ethnicity, nationality, religion, gender, sexual orientation, disability, or age), obscene, or gratuitously violent;
  • (b) constitutes or promotes child sexual abuse material (CSAM), terrorist content within the meaning of Regulation (EU) 2021/784, or other content whose mere possession or distribution is a criminal offence under Estonian or Union law;
  • (c) infringes any patent, copyright, trademark, trade secret, database right, right of publicity, or other intellectual-property or proprietary right of a third party;
  • (d) contains malware, viruses, worms, ransomware, cryptominers, trojans, backdoors, keyloggers, or any other code designed to disrupt, damage, or gain unauthorised access to a system, network, or data;
  • (e) contains sensitive categories of personal data (Article 9 GDPR) unless the Customer has a lawful basis and appropriate safeguards, and has notified the Provider where required by the DPA; or
  • (f) contains payment-card data in scope of PCI DSS beyond what is transmitted through the Provider's designated payment integrations (the Service is not certified as a PCI DSS storage environment).

3.2. The Provider does not routinely monitor Customer Data (GTC clause 10.1). Where the Provider is credibly notified of prohibited content, or becomes aware of it in the course of operating the Service, the Provider may act under Section 8 below and, where required by law, notify competent authorities.

4. Prohibited conduct

The Customer must not, and must not permit any Authorised User or third party to:

4.1. System integrity. Probe, scan, test the vulnerability of, reverse-engineer, decompile, or disassemble the Service, or attempt to bypass any authentication, access-control, rate-limit, tenancy-isolation, or security mechanism, except (a) to the extent expressly permitted by mandatory law, or (b) under a written vulnerability-disclosure or bug-bounty arrangement with the Provider.

4.2. Denial of service. Engage in denial-of-service, distributed denial-of-service, resource-exhaustion, or similar activity against the Service, its infrastructure, or other customers of the Service.

4.3. Unauthorised access. Access or attempt to access any account, tenant, data, system, or network that the Customer is not authorised to access; use stolen, purchased, or otherwise illegitimately obtained credentials; or share credentials in a manner that circumvents seat limits or tier boundaries.

4.4. Fraud and financial crime. Use the Service to commit or facilitate fraud (including invoice fraud, business-email compromise, and false-billing schemes), money laundering, terrorism financing, sanctions evasion, tax evasion, or any other financial crime.

4.5. Spam and unsolicited communications. Use the Service (including any email, notification, quotation, or invoicing feature) to send unsolicited commercial communications in breach of Directive 2002/58/EC (as amended), Estonian Electronic Communications Act, or the CAN-SPAM Act (US) where applicable; harvest email addresses or contact data other than for the Customer's legitimate business purposes; or forge headers, sender identifiers, or routing information.

4.6. Impersonation and deception. Impersonate any person or entity, misrepresent an affiliation with the Provider or any third party, or generate documents (invoices, quotes, contracts, receipts, statements) that are materially false or misleading.

4.7. Reselling and competing use. Resell, sublicense, white-label, timeshare, or otherwise make the Service available to third parties as a standalone offering, except as expressly agreed in writing (GTC clause 5.2(e)); use the Service to build a product that competes with the Service, or to copy features, functions, user interface elements, workflows, or datasets of the Service (GTC clause 5.2(f)).

4.8. Infrastructure abuse. Impose disproportionate load on the infrastructure, including through scraping, scripted mass-operations outside documented APIs, artificially inflated seat counts, headless-browser automation that mimics interactive use, or the storage of data that is not related to the Customer's own business (see Section 6).

4.9. Prohibited industries. Without the Provider's prior written consent, use the Service to run activities that are prohibited under Estonian law or that require specific licensing the Customer does not hold, including: unlicensed banking, payment services, e-money issuance, or crypto-asset service provision; unlicensed gambling; production or distribution of controlled substances, weapons, or dual-use items subject to Regulation (EU) 2021/821; or activities on the EU consolidated sanctions list.

4.10. Circumvention of tier limits. Circumvent or attempt to circumvent seat, storage, API-call, module, or feature limits associated with the Customer's tier (GTC clauses 3.2 and 5.2(d)), including by (a) creating multiple accounts to obtain additional Free-Tier allocations, (b) sharing a single seat across multiple natural persons, or (c) routing operations through third-party intermediaries designed to obscure identity or usage.

5. Data protection and personal data

5.1. The Customer is the controller of the personal data it processes through the Service unless another controller relationship is established in writing (GDPR arts. 4(7) and 26). The Provider acts as processor in accordance with the data-processing addendum ("DPA") referenced in GTC clause 10.3.

5.2. The Customer must, before uploading or generating any personal data through the Service:

  • (a) identify a valid lawful basis under GDPR art. 6 (and, for special categories, art. 9);
  • (b) inform data subjects as required by GDPR arts. 13 and 14, including the fact that a Service is used as a processor;
  • (c) implement appropriate organisational and technical safeguards on its side (GDPR art. 32), including least-privilege access, prompt de-provisioning of leavers, and use of the Service's role and permission features;
  • (d) execute the DPA where any personal data is processed through the Service (a shrink-wrap acceptance of these GTC alone is not a substitute for a DPA where mandatory).

5.3. The Customer must not upload or generate through the Service:

  • (a) personal data of children under the age of 13 (or the higher national age of digital consent under GDPR art. 8), except where the Customer has verifiable parental consent and has notified the Provider;
  • (b) personal data collected in breach of applicable data-protection law; or
  • (c) special categories of personal data (GDPR art. 9) beyond the minimum necessary for the Customer's stated business purpose.

5.4. Where the Customer discovers a personal-data breach affecting Customer Data, the Customer must notify the Provider without undue delay through the process set out in the DPA, and cooperate reasonably in the joint response.

6. Fair use of infrastructure and API

6.1. The Provider operates the Service on shared multi-tenant infrastructure. All Customers are expected to use the Service consistently with the tier they have subscribed to and with the published usage limits. The Provider may publish reasonable fair-use guidance (rate limits, storage caps, per-endpoint quotas, retention windows for logs and audit trails) in-product or in the API documentation; those guidelines are binding on the Customer.

6.2. Programmatic access must be through the Provider's documented APIs, using the Customer's own credentials, and must respect the rate limits and pagination conventions published in the documentation. Undocumented endpoints, private tokens, or internal identifiers must not be relied upon.

6.3. The Service is not intended to be used as (a) a general-purpose file-storage or backup service, (b) a data-warehouse or business-intelligence platform for arbitrary third-party data, or (c) a content-delivery network for unrelated media. Data stored in the Service must relate to the Customer's own business operations and be within the categories of data the Service is designed to hold (customers, suppliers, staff, invoices, quotes, products, and related records).

6.4. Where the Customer's usage substantially exceeds published fair-use thresholds, the Provider may (a) throttle or rate-limit the Customer's access, (b) request that the Customer upgrade to a higher tier or a bespoke plan, and (c) as a last resort, apply the suspension mechanism in Section 8.

7. Third-party integrations and content

7.1. Where the Service offers integrations with third-party services (payment processors, tax authorities, e-invoicing networks, identity providers, calendar or communication tools), the Customer's use of those integrations is subject to the terms of the third party as well as this AUP and the GTC. The Customer is responsible for authenticating to and complying with those third parties.

7.2. The Customer must not use Service integrations to (a) exceed rate limits or otherwise abuse the third party, (b) misrepresent the origin of requests, or (c) transmit content that would breach this AUP if stored directly in the Service.

7.3. Third-party content displayed inside the Service (for example, product data, exchange rates, or reference registries) is provided for convenience and without warranty (GTC clause 8). The Customer must independently verify such content before relying on it for decisions with material legal or financial consequences.

8. Reporting, investigation, and enforcement

8.1. Reporting. Any person may report suspected violations of this AUP by email to info@erpflow.ai. Reports should include (a) the URL, workspace, or account concerned, (b) a description of the suspected violation, and (c) supporting evidence to the extent available. The Provider will acknowledge receipt and treat the report confidentially to the extent consistent with the investigation.

8.2. Investigation. The Provider may investigate suspected violations, including by reviewing account metadata, logs, and — where strictly necessary and consistent with the DPA — Customer Data. Where the suspected violation involves an offence for which mandatory law requires reporting (for example, CSAM, or terrorist content under Regulation (EU) 2021/784), the Provider will comply with those obligations without additional notice to the Customer.

8.3. Interim measures. Where the Provider reasonably believes that continued use of the Service would create a legal, security, integrity, or reputational risk (GTC clause 12.1(b)), the Provider may take proportionate interim measures, including (a) rate-limiting or throttling, (b) restricting a specific feature or integration, (c) locking a specific Authorised User account, or (d) suspending the Customer's access to the Service in whole or in part.

8.4. Enforcement escalation. Enforcement generally follows a proportionate ladder: (a) notice to the Customer with a reasonable opportunity to remedy; (b) restriction of the specific behaviour or feature; (c) suspension under GTC Section 12; (d) termination for cause under GTC clause 13.3 for material or uncured breach; and (e) reporting to competent authorities where required by law. The Provider may skip earlier steps where the violation is manifestly unlawful, ongoing, or causes immediate risk (GTC clause 12.1).

8.5. No obligation to monitor. Nothing in this AUP obliges the Provider to monitor Customer Data or user activity generally. Article 8 of Regulation (EU) 2022/2065 (Digital Services Act), where applicable, applies without prejudice to the Provider's ability to act on notices and its own knowledge.

8.6. Effects of enforcement. Enforcement action does not relieve the Customer of any obligation, including the obligation to pay fees for the applicable Billed Period (GTC clause 12.2). Where enforcement leads to termination, GTC clauses 13.4 and 13.5 (effects of termination and data export) apply.

9. Changes to this AUP

9.1. The Provider may update this AUP from time to time. Material changes will be notified on thirty (30) days' prior notice by email to the account email address and/or by in-product notification; non-material clarifications and additions consistent with the existing policy may take effect on publication.

9.2. If a material change is adverse to the Customer, the Customer may terminate the Agreement in accordance with GTC clause 13.2 with effect from, at the latest, the end of the then-current Billed Period. Continued use of the Service after the effective date of a material change constitutes acceptance.

9.3. Changes required by law, regulation, or a competent authority, and changes that are neutral or favourable to the Customer, may take effect on shorter notice or immediately.

10. Interaction with other policies

10.1. This AUP is one of the policies referenced in GTC 19.1. It sits alongside:

  • (a) the GTC (governing document);
  • (b) the DPA (personal-data processing);
  • (c) the Provider's privacy notice (processing of the Customer's own personal data as controller); and
  • (d) any product-specific terms published in-product for particular modules or features.

10.2. In case of conflict, the order of precedence in GTC clause 19.2 applies.


Contact

Info@erpflow.ai

Mulai gratis. Tumbuh tanpa ganti aplikasi.

Jalankan seluruh bisnis Anda dari satu tempat — dan bayar seperti bisnis kecil, bukan seperti korporasi.

Tanpa kartu · Tanpa hitung mundur uji coba · Ekspor semua data · Batalkan kapan saja