Acceptable Use Policy
Acceptable Use Policy
EXTERNAL --- CLEARED FOR CLIENT DISTRIBUTION
Governing Permitted and Prohibited Use of the ZINFI Unified Partner Management (UPM) Platform
Prepared by ZINFI Technologies, Inc.
Created September 18, 2026
Executive Summary
This Acceptable Use Policy ("AUP") defines what customers, their administrators, and their partner users may and may not do with the ZINFI Unified Partner Management (UPM) platform. It is incorporated by reference into the ZINFI UPM Terms of Use and every ZINFI Subscription Order Form.
- ZINFI grants broad, flexible use of the UPM platform within the entitlements purchased --- this policy restricts conduct, not creativity, and is not a limit on legitimate partner ecosystem operations.
- Prohibited conduct falls into seven categories: unlawful activity, platform-integrity attacks, data and privacy misuse, harmful content, unsolicited communications, AI misuse, and unauthorized resale or competitive exploitation.
- ZINFI does not routinely monitor customer content, but reserves the right to investigate suspected violations and to suspend access where continued use presents an imminent risk to the platform, to other customers, or to third parties.
- Security researchers acting in good faith under the ZINFI Vulnerability Disclosure Policy are not in violation of this AUP; unauthorized penetration testing is.
- Enforcement is graduated --- notice and cure is the default, and immediate suspension is reserved for imminent harm, unlawful activity, or repeated violation.
1. Purpose and Scope
1.1 Purpose
This Acceptable Use Policy establishes the conduct standards that govern access to and use of the ZINFI Unified Partner Management (UPM) platform and all associated ZINFI services, APIs, portals, and websites. Its purpose is to protect the security, availability, and integrity of the platform for every customer, to protect the partner and personal data processed within it, and to ensure that ZINFI meets its obligations to its customers, their partners, and applicable regulators.
This policy states restrictions on conduct. It does not restrict the legitimate operation of a partner program within the entitlements a customer has purchased.
1.2 Scope
This policy applies to:
- All customers that have licensed the ZINFI UPM platform under a Subscription Order Form, and all of their internal users.
- All partner users, resellers, distributors, agents, and other third parties granted access to a customer's UPM deployment.
- All access methods, including the web portal, mobile applications, published APIs, connectors, and any embedded or syndicated ZINFI functionality.
- All ZINFI public websites and any evaluation, trial, proof-of-concept, or sandbox environment provided by ZINFI.
A customer is responsible for the acts and omissions of every user it provisions, including its partner users. Where this policy imposes an obligation on a user, the customer is responsible for ensuring that obligation is met.
1.3 Relationship to Other ZINFI Agreements
This policy is incorporated by reference into the ZINFI UPM Terms of Use and into each Subscription Order Form. Where this policy conflicts with an executed Subscription Order Form or a negotiated master agreement between ZINFI and a customer, that executed agreement controls. Where this policy conflicts with the ZINFI Data Processing Addendum on a matter of personal data processing, the Data Processing Addendum controls.
Related ZINFI documents: UPM Terms of Use, Data Processing Addendum (DPA), AI and Partner Data Usage Policy, List of Sub-Processors, Vulnerability Disclosure Policy. All are available through the ZINFI Trust and Compliance Center.
1.4 Definitions
- Customer --- the contracting entity that has licensed a ZINFI UPM deployment.
- Deployment --- the logically isolated instance of the ZINFI platform provisioned for a single customer.
- User --- any individual granted credentials to a deployment, whether an employee of the customer or of a partner organization.
- Partner User --- a user belonging to a partner, reseller, distributor, or agent organization within the customer's partner ecosystem.
- Customer Content --- data, documents, media, templates, and communications uploaded to or generated within a deployment by or on behalf of the customer.
- AI Feature --- any capability within the platform that uses a machine learning model, large language model, or automated scoring or recommendation system, as defined in the ZINFI AI and Partner Data Usage Policy.
2. Permitted Use
2.1 Licensed Use
Customers may use the UPM platform for any lawful business purpose relating to the recruitment, onboarding, enablement, marketing, selling, incentivizing, and support of their partner ecosystem, within the module entitlements, partner bands, and user bands set out in their Subscription Order Form.
2.2 Partner User Access
Customers may grant access to partner users at no additional per-seat charge within their licensed partner band. Customers must ensure that each partner organization is bound by terms at least as protective as this policy before access is granted, and must revoke access promptly when a partner relationship ends.
2.3 Administrator Responsibilities
Customer-designated administrators configure roles, permissions, workflows, and AI feature enablement within their own deployment. Administrators are responsible for:
- Provisioning and de-provisioning users promptly and accurately, including on employment or partnership termination.
- Applying the principle of least privilege when assigning roles and profiles.
- Safeguarding administrative credentials and enabling available authentication controls, including single sign-on and session policies.
- Configuring approval workflows where required by this policy or by the ZINFI AI and Partner Data Usage Policy.
- Notifying ZINFI without undue delay of any known or suspected unauthorized access to the deployment.
3. Prohibited Use
Customers and users must not engage in, permit, or assist any of the following.
3.1 Unlawful and Infringing Activity
- Violating any applicable law, regulation, sanctions regime, or export control restriction.
- Infringing the intellectual property, publicity, or privacy rights of any person or organization.
- Uploading, distributing, or co-branding content the customer does not have the right to use or sublicense.
- Using the platform to facilitate fraud, money laundering, bribery, or corrupt payments, including through incentive, rebate, or rewards modules.
3.2 Platform Integrity and Security
- Attempting to gain unauthorized access to any deployment, account, system, or dataset, including any other customer's deployment.
- Probing, scanning, or testing the vulnerability of the platform except as expressly permitted under Section 4.
- Circumventing or attempting to circumvent authentication, authorization, rate limiting, tenancy isolation, or entitlement controls.
- Introducing malware, ransomware, logic bombs, or any code intended to disrupt, damage, or gain unauthorized access.
- Conducting denial-of-service activity, or generating load intended or reasonably likely to degrade service for other customers.
- Reverse engineering, decompiling, or disassembling any part of the platform, except where that right cannot lawfully be excluded.
- Using automated means to scrape, harvest, or extract data at a volume or frequency inconsistent with documented API limits.
3.3 Data and Privacy Misuse
- Uploading personal data without a valid lawful basis, or in breach of any notice or consent obligation owed to the data subject.
- Uploading special categories of personal data, government identifiers, payment card data, or protected health information unless expressly agreed in writing with ZINFI.
- Using partner personal data for a purpose materially incompatible with the purpose for which it was collected.
- Exporting or transferring partner personal data in breach of applicable cross-border transfer requirements.
- Attempting to re-identify anonymized or aggregated data.
3.4 Content Standards
- Publishing or distributing content that is defamatory, harassing, discriminatory, obscene, or that promotes violence or unlawful activity.
- Publishing content that impersonates ZINFI, the customer, a partner, or any other person or organization.
- Using co-branding, syndication, or microsite capabilities to make false or misleading claims about a product, service, price, or affiliation.
3.5 Communications and Anti-Spam
- Sending unsolicited commercial communications in breach of applicable law, including CAN-SPAM, CASL, GDPR, and equivalent regimes.
- Sending communications to lists not lawfully obtained, or to recipients who have withdrawn consent or opted out.
- Falsifying sender identity, headers, or routing information, or omitting a functioning unsubscribe mechanism where one is required.
- Using partner marketing, email, social syndication, or event modules to distribute content prohibited under Section 3.4.
3.6 AI-Specific Prohibited Use
The following apply in addition to the controls set out in the ZINFI AI and Partner Data Usage Policy.
- Disabling, removing, obscuring, or misrepresenting AI output labelling, which cannot be disabled by configuration.
- Bypassing a required human review step before an AI-generated output is delivered to a partner or acted upon externally.
- Using AI features to make or materially inform a consequential decision about an individual without human review.
- Submitting prompts or content designed to cause an AI feature to produce unlawful, harmful, or deceptive output, or to disclose data outside the customer's own deployment.
- Attempting to extract, reconstruct, or reverse engineer any underlying model, model weights, or system instructions.
- Representing AI-generated content as human-authored where applicable law requires disclosure.
3.7 Resale, Benchmarking, and Competitive Use
- Reselling, sublicensing, leasing, or providing the platform as a service bureau to any third party, except as expressly permitted in the Subscription Order Form.
- Sharing credentials, or permitting use by anyone other than the named or licensed user.
- Accessing the platform to build, train, or benchmark a competing product or service, or publishing benchmark results without ZINFI's prior written consent.
- Exceeding licensed partner bands, user bands, or module entitlements through technical or administrative circumvention.
4. Security Testing and Research
4.1 Authorized Testing
Customers may not conduct penetration testing, vulnerability scanning, or red-team exercises against the ZINFI platform without prior written authorization from ZINFI. Where authorization is granted, testing must be confined to the customer's own deployment or a ZINFI-designated test environment, must observe an agreed scope and window, and must not target other customers, shared infrastructure, or ZINFI sub-processors.
4.2 Good-Faith Vulnerability Disclosure
Security researchers acting in good faith and in accordance with the ZINFI Vulnerability Disclosure Policy do not violate this Acceptable Use Policy. Good faith requires that the researcher makes no attempt to access, modify, or exfiltrate data belonging to any party other than themselves, causes no service degradation, and reports findings to ZINFI before any public disclosure.
5. Enforcement
5.1 Monitoring
ZINFI does not routinely monitor Customer Content. ZINFI does monitor platform-level telemetry --- authentication events, API call patterns, resource consumption, and security signals --- for the purpose of maintaining security, availability, and entitlement compliance. ZINFI may review Customer Content where it has a reasonable basis to suspect a violation of this policy, where required by law, or where necessary to respond to a security incident.
5.2 Investigation and Response
Where ZINFI identifies a suspected violation, ZINFI will ordinarily notify the customer, describe the conduct at issue, and provide a reasonable opportunity to investigate and remediate before taking further action.
5.3 Suspension and Termination
ZINFI may suspend access to an affected feature, user account, or deployment without prior notice where continued use presents an imminent risk to the security, availability, or integrity of the platform, to another customer, or to a third party; where the conduct is unlawful; or where ZINFI is required to act by law or by a competent authority. ZINFI will restrict any suspension to the narrowest scope reasonably sufficient to address the risk, will notify the customer as soon as reasonably practicable, and will restore access promptly once the risk is resolved. Repeated or unremediated violation may result in termination in accordance with the customer's agreement.
5.4 Reporting a Violation
Suspected violations of this policy, including abuse originating from a ZINFI-hosted deployment, should be reported to ZINFI using the contact details published in the ZINFI Trust and Compliance Center. Suspected security vulnerabilities should be reported under the ZINFI Vulnerability Disclosure Policy rather than through general support channels.
6. Changes to This Policy
ZINFI reviews this policy at least annually. ZINFI may update it to reflect changes in the platform, in applicable law, or in the threat environment. Where a change materially increases a customer's obligations or materially restricts permitted use, ZINFI will provide at least thirty (30) days' notice before the change takes effect. Every version carries a version number and an effective date, and prior versions are retained and available on request.
Policy version: This is Version 1.0 of the ZINFI Acceptable Use Policy, effective September 18, 2026. Owner: ZINFI Technologies Information Security and Privacy Office. Next scheduled review: September 2027, or sooner if the platform, the regulatory landscape, or customer requirements materially change.
Closing Summary
This Acceptable Use Policy sets the conduct boundary for the ZINFI Unified Partner Management (UPM) platform: broad permitted use within purchased entitlements, seven categories of prohibited conduct, a good-faith safe harbor for security research, and graduated enforcement that defaults to notice and cure rather than suspension.
- Review this policy with your legal and compliance team and confirm alignment with your organization's vendor use requirements.
- Confirm that every partner organization with access to your deployment is bound by terms at least as protective as this policy.
- Review administrator role assignments against the least-privilege standard in Section 2.3.
- Confirm your AI feature configuration meets the labelling and human-review requirements in Section 3.6.
- Contact ZINFI through the Trust and Compliance Center with any questions about permitted use, authorized security testing, or reporting a violation.
zinfi.com/trust-compliance-center