Acceptable Use Policy (AUP)
Effective Date: September 19, 2026 | Version 2.1
01.Purpose & Applicability
This Acceptable Use Policy ("AUP") defines the rules governing the use of ApexCal SaaS ("Platform"), including appointment booking widgets, staff administration tools, WhatsApp AI Receptionist workflows, and backend REST APIs.
This policy applies to all Tenant Organizations, Administrators, Staff members, and End Users. Violation of this AUP may result in immediate suspension or permanent termination of platform access.
02.WhatsApp & Automated Messaging Compliance
When utilizing the WhatsApp AI Receptionist or automated SMS/email reminder features, tenants must strictly adhere to the following standards:
- Customer Opt-In Consent: You must have explicit, verified consent from end customers before initiating automated booking messages or appointment reminders to their phone numbers.
- No Unsolicited Commercial Spam: Using the WhatsApp AI integration to send bulk promotional marketing, unrequested cold outreach, or unsolicited broadcasts is strictly prohibited.
- Honor Opt-Outs: You must immediately cease messaging any customer who replies with STOP, UNSUBSCRIBE, or asks to be removed from reminders.
- Meta / WhatsApp Policy Compliance: All messaging must comply with WhatsApp Business Messaging Policies and applicable telecommunications regulations (e.g., TCPA, CTIA guidelines).
03.Prohibited Activities
Attempting to bypass multi-tenant row-level security (`tenant_id`), probing API vulnerabilities, executing SQL injection, or inspecting other organizations' appointment records.
Using automated bots to flood public booking schedules, hoard appointment slots, execute credential-stuffing attacks, or scrape directory endpoints.
Circumventing API rate limits, launching Denial of Service (DoS) attacks, or placing excessive load on shared database clusters.
Storing or transmitting content that is defamatory, fraudulent, infringes on intellectual property, or facilitates illegal services.
04.API & Rate Limiting Enforcement
ApexCal enforces automated rate limits across public booking endpoints and authenticated API routes to ensure service reliability:
- Public booking submission endpoints: Rate-limited to prevent appointment slot spam.
- Authentication routes: Protected against brute-force login attempts with temporary IP throttling.
- Webhook processing: Protected by signature validation and replay defense.
05.Reporting Violations & Enforcement
If you discover a security vulnerability or suspect an organization is abusing the platform to transmit spam or illegal content, please report it immediately:
ApexCal Abuse & Security Desk
Email: support@apexcal-saas.xilxil.com
Abuse Ticket Form: apexcal-saas.xilxil.com/contact