Acceptable Use Policy
WorkOSync is shared infrastructure that thousands of businesses depend on. This policy sets the rules that keep it safe, lawful and fast for everyone. It forms part of the Terms of Service and applies to every user of every company on the platform.
Purpose and scope
This policy applies to all use of the WorkOSync website, web application, mobile apps, APIs and any service we operate (the “Service”), by any account holder, invited user, API client or visitor. The Customer is responsible for ensuring that everyone it invites into its company follows this policy. Capitalised terms have the meanings given in the Terms of Service.
Prohibited content
You may not upload, store, generate or transmit through the Service any content that:
- Is unlawful under the laws of the United Arab Emirates or of the country from which you use the Service, including content that offends public order or morals, promotes hatred or discrimination, or supports terrorism.
- Infringes the copyright, trade mark, trade secret, privacy or other rights of any person.
- Contains malware, ransomware, exploits, or code designed to damage, intercept or take control of any system.
- Is sexually explicit, depicts child sexual abuse, or exploits minors in any way. We report such content to the authorities.
- Is defamatory, threatening, harassing or fraudulent.
- Consists of personal data that you have no lawful right to process, including lists purchased or scraped without a lawful basis.
Prohibited conduct
- Accessing, or attempting to access, any company, account, data or system that you are not authorised to use, including by guessing credentials, exploiting a bug, or altering an identifier in a request.
- Probing, scanning or testing the vulnerability of the Service, or breaching any security or authentication measure, other than under section 8.
- Interfering with the Service: denial-of-service attacks, flooding, deliberately triggering rate limits, or introducing load intended to degrade it for others.
- Scraping or harvesting data from the Service with automated tools, or bypassing the bot and abuse protections we operate.
- Reverse engineering, decompiling or copying the Service, or building a competing product from it.
- Sharing a single user login between several people, or exceeding the seats on your plan through shared credentials.
- Reselling, sublicensing or offering the Service to third parties as a bureau, without a written reseller agreement with us.
- Impersonating WorkOSync, another business or another person, or misrepresenting your affiliation.
- Using the Service to evade sanctions, or from a country or on behalf of a person subject to UAE, UN, EU, UK or US sanctions.
Email, SMS and WhatsApp messaging
WorkOSync can send invoices, statements, reminders, quotes and campaigns by email, SMS and WhatsApp on your behalf. When you use these features you must:
- Send only to people who have a genuine business relationship with you or who have consented to hear from you. Purchased, rented or scraped lists are not permitted.
- Comply with the UAE Telecommunications and Digital Government Regulatory Authority (TDRA) rules on unsolicited electronic communications, the PDPL, the WhatsApp Business messaging policies, and, for recipients abroad, laws such as the GDPR, the ePrivacy Directive, CAN-SPAM and CASL.
- Identify your business truthfully in every message and include a working way to opt out of marketing messages. Opt-outs must be honoured within 10 days; the Service applies them automatically.
- Not send messages whose content is prohibited under section 2, or that are deceptive about their sender, subject or purpose.
Complaint and bounce rates are monitored. Sending that produces excessive complaints, spam-trap hits or bounces will be paused, and repeated abuse results in permanent loss of messaging features.
AI features
The AI layer is provided to help you run your own business. You may not use it, whether with WorkOSync-managed AI or your own key, to:
- Generate content that is prohibited under section 2, or that provides instructions for causing serious harm to people, property or systems.
- Produce material that deceives people about its origin, such as fake reviews, forged documents, impersonation of real people, or deepfakes.
- Make automated decisions with legal or similarly significant effects on individuals, such as hiring, firing or credit decisions, without meaningful human review. AI output in WorkOSync is always a draft for a person to approve.
- Attempt to extract another customer’s data, our system prompts or the model provider’s proprietary information, or to bypass safety controls.
- Breach the acceptable use terms of the AI provider whose key you have connected.
Payments and financial records
WorkOSync records your ledger and can collect payments from your clients through the gateways you connect. You must not use these features to launder money, finance terrorism, evade tax, issue fictitious invoices, process payments for goods or services that are illegal or prohibited by your gateway, or process transactions for a business other than the one registered on the account. You must comply with the gateway’s own terms, with UAE Federal Tax Authority requirements for tax invoices and record keeping, and with the anti-money-laundering obligations that apply to your business. We cooperate with lawful requests from tax and law-enforcement authorities.
Fair use and resource limits
Plans include generous storage, API and AI allowances designed for real business use. To protect performance for everyone, we apply per-company limits on API requests, outbound messages, AI requests, file size and storage. Automated use that materially exceeds the pattern of an ordinary business of your size, or that is designed to circumvent seat or plan limits, may be throttled. Where use is consistently above plan limits we will contact you to move to a suitable plan before any restriction is applied.
Security research and responsible disclosure
We welcome good-faith security research. You may test the Service for vulnerabilities only against your own company and accounts, without degrading the Service or accessing other customers’ data, and without using automated scanners at volume, social engineering, physical attacks or denial of service. Report findings to security@workosync.com and give us a reasonable time to fix them before any disclosure. Research conducted under these rules will not be treated as a breach of this policy, and we will not pursue legal action for it. Full details are on the Security Overview page.
Enforcement
We investigate reported and detected breaches of this policy. Depending on severity we may remove content, throttle or disable a feature, suspend a user or a company, or terminate the agreement under the Terms of Service. We give notice and a chance to remedy where the breach is not causing ongoing harm, and act immediately where it is, for example an active attack, malware or illegal content. Our abuse systems also block sources automatically: addresses that trip a honeypot, probe for known vulnerabilities, brute-force a login or send spam are banned at the application and firewall level, and repeat offenders are banned permanently. We may report unlawful conduct to the relevant authorities and preserve evidence for that purpose.
Reporting abuse
If you believe someone is using WorkOSync in breach of this policy, or you received a message through the Service that you did not want, email support@workosync.com with the subject “Abuse report” and include the message, the sender, the time and any headers or links. We acknowledge every report within one working day and act on verified reports promptly. We do not disclose the identity of a reporter to the person reported.
Changes to this policy
We update this policy as new features and new forms of abuse appear. Changes take effect when published here, and material changes are announced by email to account owners in advance. Continued use of the Service after a change means you accept it.
Contact
Questions about this document, or a request under it, can be sent to the address below. We reply within one working day, Sunday to Thursday.
Other addresses: privacy@workosync.com for data protection, support@workosync.com for billing and support, security@workosync.com for vulnerability reports.

